cyberx_█
Report
← back to indexCompliance & Regulation7 min read

The BC pushed the cutoff for unauthorized exchanges to 6 November and promised a list the rule itself never defines

The Banco Central moved from 30 October to 6 November the date on which banks and payment institutions are barred from doing business with unauthorized virtual asset service providers, and the text no longer mentions those still under review. The vote underpinning the change says the extra week is for publishing the official list of firms in transition.

Robert F.
The BC pushed the cutoff for unauthorized exchanges to 6 November and promised a list the rule itself never defines
▸In this article

On 25 September the Banco Central published Resolução BCB nº 589, amending Resolução BCB nº 520, the rule governing virtual asset service providers, or PSAVs. Much of the coverage treated the change as a one-week postponement. It is a postponement, but it is not only that.

The article at issue is art. 91, which we explained here back when the date was still 30 October. It bars banks, payment institutions and other BC-authorized institutions from "carrying out or enabling" transactions with irregular providers — which includes holding their accounts and processing their payments.

What changed in the text

Original wordingWording under Res. 589
Dateas of 30 October 2026as of 6 November 2026
Prohibited counterpartyentities that "are not authorized or in the process of authorization to operate in the country"institutions or entities that "are not authorized to operate in the country"
Carve-out"except in the forms expressly authorized in this Resolution"unchanged

The date moved, and the reference to anyone "in the process of authorization" dropped out of the text. Under the original wording, a provider that had filed its application within the deadline remained a permitted counterparty. Under the new one, read literally, only an already authorized provider is.

The BC's statement says something else

The statement with which the Banco Central announced the change, dated 23 September, describes the amendment as an adjustment to the "operational deadline for other institutions to cease transactions whose counterparties are entities that are not authorized or in the process of authorization."

That is the construction of the old wording: the prohibition reaches those who are neither authorized nor under review. The statement speaks as though the carve-out still stood; the binding text no longer contains it.

The vote explains the extra week

The clearest answer is found neither in the resolution nor in the statement, but in Voto 108/2026-BCB, dated 22 September, signed by the Director of Regulation, who brought the change before the Collegiate Board. It says why the date moved by a week:

"This additional period will allow this Authority to systematize and publish the official list of institutions in transition, including virtual asset service providers and eligible institutions already in operation that have notified their intention to operate in the virtual asset market or have filed an authorization request for that same purpose, ensuring clarity and legal certainty for the market and for government bodies."

— Voto 108/2026-BCB, item 7

And, in the following item, how the rule stands as of the new date:

"With this adjustment, as of the date indicated, regulated institutions are expressly prohibited from transacting with counterparties that are not duly authorized, save for the exceptions provided in the rule."

— Voto 108/2026-BCB, item 8

The deadline for a provider to file its application ends on 30 October. The prohibition kicks in a week later. The vote says that week is for the BC to publish who has notified an intention to operate or filed an application. A list of firms in transition is only useful to a bank if being on it changes something. The reading this design suggests is that a provider in transition may still be served.

What the rule does not say

The resolution, however, does not say that. It makes no mention of the list, and the vote refers to "the exceptions provided in the rule" without specifying which.

The possible bridge lies in another article of the same resolution. Art. 88, § 6 states that a provider that applied for authorization within the deadline "may continue providing virtual asset services until its authorization process is concluded." One can argue that serving such a provider is one of the "forms expressly authorized in this Resolution" — the carve-out art. 91 retained. It is a plausible reading, and it is not written anywhere: § 6 authorizes the provider to operate, not the bank to act as its counterparty.

The weight of that difference shows up on the calendar. The maximum period for the BC to decide on the authorization request of a provider already in operation is up to 1,080 days, in two phases of up to 360 and 720 days, set out since Resolução BCB nº 549 in February. Resolução BCB nº 594, published on 2 October, kept that ceiling for applications filed from its effective date onward, which covers everything still to arrive by 30 October. Read literally, art. 91 would leave a provider operating lawfully under § 6 while simultaneously having no bank and no payment account as of 6 November — possibly for years.

For anyone running compliance at a regulated institution, the practical consequence is that the resolution alone is not enough to decide what to do on 6 November. You have to watch for the publication of the list and whatever the BC says alongside it.

The dates, in order

  • 30 October 2026: deadline for a provider already operating on 2 February to apply for authorization (art. 88, I, of Res. 520).
  • 6 November 2026: the art. 91 prohibition takes effect. According to the vote, the week between 30 October and this date is for the BC to systematize and publish the official list of institutions in transition.
  • 29 November 2026: a provider that failed to apply within the deadline must have wound down its services, no more than 30 days after 30 October (art. 88, § 7).
  • 1 January 2027: the new data reporting rules to the BC take effect (below).

What changes in January

Res. 589 also alters reporting to the Banco Central. Today, a provider in transition reports client balances and custody positions daily, and proof of reserves plus the total allocated to staking monthly, from filing until the conclusion of phase 1 of the authorization process. As of 1 January 2027, the frequency drops out of the text and will follow specific BC regulation, and reporting no longer ends at phase 1.

The obligation also extends to banks and other authorized institutions that provide virtual asset services (arts. 90-A and 90-B). According to the vote, the aim is to standardize data and formats across everyone active in this market.

And Coaf

On the same day as 589, the BC published Resolução BCB nº 588, requiring institutions to report to Coaf any virtual asset transfers to or from self-custodied wallets at or above the equivalent of US$ 10,000, as well as foreign exchange transactions in physical foreign currency at the same threshold. A week later, Resolução BCB nº 591 revoked 588 and republished it with one addition: transactions carried out between 1 October and 31 December 2026 will be reported in a single batch, on the first business day of January 2027. The obligation has applied since 1 October; the reporting for that quarter only reaches Coaf in January.

In one line

The BC pushed to 6 November the prohibition on banks and payment institutions serving unauthorized virtual asset providers and, in the vote, promised a list of those in transition. The resolution still does not say what being on that list guarantees.

This article will be updated when the Banco Central publishes the official list of institutions in transition.

Sources

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.

Related reading

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

how we write →